Cross-Organization Threat Discovery via Clustering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security threat detection systems face challenges in accurately identifying malicious attacks, particularly when covert techniques are employed, leading to a high number of false positive alerts due to low fidelity indicators of compromise, which require costly manual analysis and hinder effective threat detection across various organizations.
Innovation Solution
A system and method that utilize clustering and similarity analysis of security data to generate risk scores for potential attacks, incorporating indicators of compromise, forensic information, and additional clustering information to identify and predict new threats, while dynamically updating indicators and scores based on new data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If low fidelity indicators of compromise are used to detect covert cyber-attacks, then the ability to detect malicious attacks is improved, but the number of false positive alerts increases
Solution Approach 1:
The patent combines multiple low fidelity indicators of compromise from multiple organizations into a collective intelligence system. By merging data across organizational boundaries and applying clustering algorithms, the system transforms individual low-fidelity signals into high-fidelity threat detections through pattern recognition across the collective dataset.
Solution Approach 2:
The system implements feedback loops where detected threats and false positives are used to continuously refine the clustering algorithms and indicator weighting. The collective intelligence system learns from each detection event, adjusting fidelity scores and detection thresholds to improve accuracy over time while reducing false positives.
2Device complexity
If traditional indicator of compromise analysis is used, then individual organization security monitoring is simplified, but the ability to detect coordinated attacks across organizations is reduced
Solution Approach 1:
The patent creates a universal security monitoring platform that serves multiple organizations simultaneously. The collective intelligence system performs multiple functions: individual organization monitoring, cross-organization pattern detection, threat correlation, and predictive analytics, all through a single multi-functional architecture that benefits all participants.
Solution Approach 2:
The system adds a new dimension to security monitoring by transitioning from single-organization isolated analysis to multi-organization collective intelligence. This dimensional shift enables detection of coordinated attacks that span multiple organizations by analyzing patterns across the expanded organizational landscape.
3Measurement precision
If manual analysis of security alerts is performed, then false positive alerts can be investigated, but the cost and time required for threat analysis increases
Solution Approach 1:
The collective intelligence system performs self-service by automatically analyzing and correlating indicators of compromise across organizations without requiring manual intervention. The clustering algorithms and predictive analytics engines autonomously process security data, identify threats, and generate detections, eliminating the need for manual false positive investigation while maintaining high accuracy.
Data Source
AI summary
The present disclosure provides systems and methods for organizations to use security date to generate a risk scores associated with potential compromise based on clustering and/or similarities with other organizations that have or may have been compromised. For example, indicators of compromise can be used to create a similarity score rank over time that may be used as a similarity and risk measurement to generate a continual/dynamic score, which can change and/or be updated as new data is created or arrives to detect or prevent threats and/or malicious attacks.


